NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

PHI Retention by Employees not a HIPAA Breach Says Ark. Court

The U.S. District Court of the Western Division of the Eastern District of Arkansas has ruled that two employees who retained the Protected Health Information (PHI) of patients after their employment at Arkansas Children’s Hospital was terminated, did not violate the Health Insurance Portability and Accountability Act (HIPAA). Unfair Contract Termination after Discovery of Billing Irregularities Pam and Eben Howard brought an action against Arkansas Children’s Hospital – Dr. Ron Robertson and Jon Bates – after their employment contracts were terminated. They believed they lost their jobs because they highlighted a number of issues relating to how the healthcare provider billed the government. They have accused the healthcare provider of violating the 1st and 14th Amendments, the Arkansas Civil Rights Act, the Public Policy of the State of Arkansas and the False Claims Act. Potential HIPAA Violations for Retention of PHI and Unauthorized Disclosure While employed at ACH, the pair collected a considerable volume of PHI of patients. After what the pair considered to be unfair...

Read More
New York State Comptroller Publishes ePHI Security Compliance Audit Report
Jul16

New York State Comptroller Publishes ePHI Security Compliance Audit Report

The news is full of reports of healthcare providers failing to implement safeguards to keep Protected Health Information (PHI) secure; but it is rare for a healthcare organization to make the headlines for implementing all of the appropriate physical, administrative and technical safeguards required by HIPAA. However, a recent ePHI data security audit conducted by the New York Office of the State Comptroller has seen Roswell Park Cancer Institute pass with no HIPAA violations discovered. The healthcare provider should be commended for the effort it has put into protecting the privacy of patients. The New York Office of the State Comptroller Audit The State of New York Office of the State Comptroller (NYOSC) conducts regular audits of state organizations, most of which are related to corporate finance. However, last week the NYOSC announced it had completed an ePHI compliance audit of Roswell Park Cancer Institute (RPCI). The audit was conducted specifically to test the safeguards the healthcare provider had put in place to secure patient data, pursuant to Article X, Section 5 of...

Read More

Insurance Service Office Announces Breach of Social Security Numbers

Insurance Service Office (ISO), a New Jersey provider of property and casualty insurance, has announced its insurance database was inappropriately accessed, resulting in a breach of Protected Health Information (PHI). ISO has not disclosed the number of individuals affected nor whether access was gained by a hacker or a malicious insider; however it does appear that data was accessed with the intent of using it for criminal purposes. The database contained highly sensitive information on patients, including details of their health insurance policy, Social Security numbers, and driver’s license numbers. Patient names, dates of birth and contact details were also stored in the database. The information exposed in the HIPAA breach could be used by criminals to steal identities, fraudulently obtain credit and make fake insurance claims. Breach Notification Delay Requested by Law Enforcement HIPAA regulations require covered entities to issue breach notifications to affected individuals within 60 days of the discovery of a PHI breach; however patients and federal/state agencies should...

Read More

2015 Biannual Healthcare Data Breach Report Released

The healthcare industry had a particularly torrid time last month with 18 data breaches reported to the OCR, exposing 1,455,863 records, the bulk of which came from the CareFirst data breach. This month the number of data breaches reported has increased to 21, although the number of new victims created was much lower, with 159,231 individuals affected. An analysis of the data breach reports for the past three years shows that little has changed since 2014, “the year of the data breach,” at least not for the better. Fewer data breaches have been reported in 2015 than in 2014, 122 compared to 131, up until the end of June. However, measure the year in the number of victims created and 2015 is on an entirely different scale. 89,439,761 new data breach victims have been created so far this year, compared to 12,503,190 last year and 851,433 in 2013. Many of this year’s victims are now data breach veterans having had their data exposed by their insurer and their healthcare provider. Biannual Data Breach Report 2014 saw a big rise in the number of reported data breaches, and this year...

Read More

BCBSA Offers Identity Theft Protection Services to All 106 Million Members

Yesterday, the Blue Cross Blue Shield Association (BCBSA) made a surprising announcement. It will be offering identity theft protection services to all 106 million of its members, in an effort to address the rapidly increasing risk of data theft and fraud. The Blue Cross and Blue Shield Association consists of 36 independent, community-based and locally-operated companies, which service the entire United States. One in three Americans has a health insurance policy run by BCBSA. The unprecedented move comes after BCBSA health plan members have suffered numerous data breaches, including the massive data breaches at Anthem, CareFirst and Premera Blue Cross. Identity theft protection services do not come cheap, especially when the unit cost must be multiplied by 106 million. This move carries a significant cost, even with a bulk discount, and shows a strong commitment to its plan members. This was a very positive, proactive step to take, and is one likely to win back the faith of many members. The new service will provide ”heightened safeguards for plan members.” BCBSA may not be able...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist